DNS is one of the oldest fundamental services of the Internet. Its role has traditionally been easy to understand: when a user enters the name of an online service into a browser, DNS tells the browser where that service can be found. Cloud services and APIs have already changed this world. DNS no longer serves only humans; vast numbers of applications, microservices, and cloud services use it to find one another. In the third phase, AI agents may change the role of DNS again, from a naming service to infrastructure for digital trust.

A bigger change lies ahead

In the future, AI agents will need to discover each other, but discovery alone is not enough. They must also be able to determine who they are dealing with and whether the other party can be trusted. As a result, DNS could become a much more important part of enterprise digital identity and trust infrastructure.

What happens when the customer is no longer a human?

Consider a fairly simple future scenario in which a company’s AI agent needs transportation services. Instead of an employee opening a browser, searching for a logistics company’s website, and placing an order, the agent could handle the entire process autonomously.

1. How does the agent know where to find the logistics company’s agent?
2. How does the logistics company know that the agent contacting it really represents the company it claims to represent?
3. What authority does the agent have to act?

Today’s Internet does not provide a single universal, vendor-independent mechanism for this. Agent discovery and identity are still largely based on mechanisms provided by individual applications, APIs, and platforms. That works within a closed ecosystem.

At Internet scale, something else is needed

DNS is a surprisingly natural solution. Companies already have a globally recognized identity on the Internet: their *domain*. DNS, in turn, provides a global, distributed system through which an organization’s services can be discovered via its domain. This is why it is particularly interesting that emerging standards proposals for AI agents envision a significant role for DNS.

In approaches such as DNS-AID and DAN, DNS could help an agent discover another organization’s agent service. A single query could provide information such as the protocol in use, the agent’s capabilities, its endpoint, and certificate-related bindings.

This would fundamentally change the model. Discovering an agent would not necessarily require a global directory operated by an AI platform provider. An organization could publish its agents through its own domain. This represents a potential third phase in the evolution of DNS and domain management — one in which AI agents change the role of DNS.

How do we know that an agent really is who it claims to be?

In my view, this is the most interesting question in the entire development. TLS protects the connection between an agent and a service. However, TLS alone does not establish the agent’s business identity. In the future, it will not be enough simply to know that a connection is encrypted. We may also need to determine:

* Is this really an agent published by the organization?
* Which version of the agent am I interacting with?
* Is the agent still active and authorized?
* Can its actions later be associated with the correct organization and identity?

The ANS v2 and DNSid proposals address precisely this identity challenge. The objective is to establish a verifiable identity for an agent and maintain its relationship with the organization that controls it, even when cryptographic keys change or the agent is retired. This is where the role of the domain becomes particularly interesting. It is no longer simply `company.com`, under which a website and email services are hosted. The domain could also become one of the anchors of an organization’s digital identity.

The importance of DNSSEC could change fundamentally

DNSSEC has existed for a long time, yet enterprise adoption has not progressed as rapidly as the technology’s age might suggest. One reason is very practical. DNS works without DNSSEC, while deploying DNSSEC introduces additional keys, processes, and dependencies that must be managed. Without automation, this can be too complex for many organizations.

The equation may change in a world of AI agents. If DNS is no longer used merely to retrieve an IP address, but also to provide information about **which agent we are interacting with**, the authenticity of DNS information becomes considerably more important.

DNSSEC provides cryptographic validation of DNS data. DANE, in turn, enables certificate and key-related trust information to be bound to DNS. In the DAN model, this becomes very concrete: DNSSEC validation is an essential requirement rather than an optional security enhancement.

A simplified future trust chain could therefore look like this: Domain → DNSSEC → organization → agent → cryptographic identity → service

That is a very different use case from traditional DNS name resolution.

DNS Security gets a new role

Another interesting development concerns Protective DNS. Today, Protective DNS solutions are typically used to prevent users and devices from connecting to known malicious domains. In a world of AI agents, the DNS resolver could become a much more active component of security policy. Before a connection is established, it might become possible to ask:

What agent is this? Who published it? Can its identity be verified? Is our agent allowed to communicate with it?

One of the objectives in this emerging vision is to enable agent policy enforcement at the resolver, before the connection is established. From a security perspective, this is a significant concept. Today, many controls are applied only when an application or gateway processes a connection that is being established or already exists. In the future, DNS could participate in the decision earlier in the process.

As a consultant, I don’t think the most interesting conclusion from these developments is which of today’s proposed standards will ultimately prevail. The standards are still evolving, and their implementation models and respective roles may change considerably.

The more interesting question is: If development moves in this direction, is today’s enterprise domain and DNS management ready for it?

In many large enterprises, the domain environment has evolved over years or even decades. Acquisitions have brought in additional domains. Different business units have used different registrars. DNS services are spread across multiple providers. Certificates are managed in separate systems. DNSSEC is deployed for some domains but not others. Responsibilities are distributed across IT, security, development, brand, legal, and external service providers.

And somewhere, the overall picture may still be maintained in an Excel spreadsheet. That is already a poor foundation for today’s digital services. As the number of AI agents grows, it could become a considerably larger problem.

AI does not scale a manual management model

This may be the most important practical observation. A world of AI agents will involve enormous numbers of machine-driven changes and machine-to-machine relationships. These cannot be managed using the same processes used for a few hundred corporate domains or certificates. If creating a new digital identity requires a ticket, an email, an Excel entry, a manual DNS change, and a separate certificate process, the architecture simply does not scale.

Centralized management and automation will be required: Domain → DNS → DNSSEC → TLS → identity → policy → audit

And controlled decommissioning is just as important as creating an identity. When a service or, in the future, an agent is retired, the associated DNS records, certificates, keys, permissions, and redirects must follow its lifecycle.

The third era of DNS?

The evolution of the Internet can, with some simplification, be viewed in three phases:

1. In the first phase, people used DNS to find services.
2. In the cloud and API era, applications increasingly used DNS to find each other.
3. In the next phase, AI agents will need to discover each other, identify each other, and determine whether they can trust each other.

If this development materializes, the role of DNS will expand once again. DNS is not going away, nor is its original purpose changing. Instead, new mechanisms are being built on top of it. DNS could become one of the key discovery and trust layers of an open Internet for AI agents.

There is no need to choose the technology in advance. The first step should be to assess the current domain, DNS, DNSSEC, and TLS environment, identify manual processes and associated risks, and define what an automated, auditable target architecture should look like. Only then should the organization evaluate which technologies are best suited to implementing it.

AI agent standards will continue to evolve. A well-managed foundation for DNS, domains, and digital trust will not be wasted, regardless of which standards ultimately become established. And if DNS really is entering its third era, it should begin before the first thousands of agents come knocking. AI agents are changing the role of DNS

 

Hannu Rokka, Senior Advisor
5Feet Networks Oy